A security researcher signs up for a free account on Lovable. Five API calls later, source code, database credentials, AI chat histories, even customer data from Nvidia, Microsoft, Uber, and Spotify employees spill out. No exploits. No zero-days. Just public projects anyone could browse. This isn’t fiction. It’s what @weezerOSINT demonstrated on April 20, 2026, claiming a ‘mass data breach’ hitting every Lovable project before November 2025. The post racked up nearly two million views. Developers panicked. Credentials rotated. Questions mounted. Lovable, the Stockholm-based ‘vibe-coding’ sensation valued at $6.6 billion after a $330 million Series B, fired back fast. ‘To be clear: We did not suffer a data breach,’ the company posted on X. Documentation on ‘public’ projects was unclear, they said. Chats used to be visible there. Code visibility? Intentional, like GitHub public repos. Enterprise users lost public options back in May 2025. But the story shifted.…